Supply chain
β Supply Chain
BORN Ontario Third-Party Breach (September 2023)
Primary Source βIncident Details
SickKids impacted by BORN Ontario data breach that hit 3.4 million. The Hospital for Sick Children, more commonly known as SickKids, is among healthcare providers that were impacted by the recent breach at BORN Ontario. The top Canadian pediatric hospital disclosed that as a part of its operations, it shares personal health information with BORN Ontario “related to pregnancy, birth and newborn care.”. The BORN Ontario data breach that impacted 3.4 million people was caused by the exploitation of well-known zero-day vulnerability ( CVE-2023-34362 ) in Progress MOVEIt Transfer software. On Monday, September 25th, SickKids disclosed that it is “among the many Ontario healthcare providers” that share sensitive health information with BORN Ontario, a perinatal and child registry that collects, interprets, shares and protects critical data about pregnancy, birth and childhood in the province of Ontario. Third-party company: Ipswitch, Inc..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Ipswitch, Inc.
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-09-01 Breach occurred
- 2023-09-26 Publicly disclosed